/var/log/secure
and /var/log/audit/audit.log
. Note: sending logs to a dedicated log server helps prevent attackers from easily modifying local logs to avoid detection.
sudo
to execute commands as root when required. Users capable of running sudo
are specified in /etc/sudoers
. Use the visudo
utility to edit /etc/sudoers
.